LiteLLM cuts ties with controversial startup Delve after malware attack
LiteLLM — one of the most popular AI gateways — is ending its partnership with startup Delve. Through Delve, the company obtained two security certifications, but last week it was hit by malware that stole credentials. Delve has long been criticized in the community — and this incident was the last straw.
AI-processed from TechCrunch; edited by Hamidun News
LiteLLM, one of the most sought-after tools for routing requests to language models, announced the termination of cooperation with startup Delve — amid a serious security incident and pressure from the community. LiteLLM used Delve to obtain two security compliance certificates. Such certificates are important for corporate clients: they signal the maturity of processes and compliance with standards like SOC 2 or ISO.
However, last week LiteLLM fell victim to a malware attack that stole credentials — one of the most dangerous types of threats, as it gives attackers direct access to systems and secrets. Delve — a startup specializing in expedited security audits — has long been a source of controversy in the tech community. Critics point to aggressive marketing practices and questionable rigor in the certifications it issues.
The LiteLLM incident intensified these concerns: a company that was supposed to help clients appear secure turned out to be associated with a partner at the moment of serious compromise. LiteLLM is widely used in the industry as a proxy layer between applications and dozens of language models — from OpenAI and Anthropic to open-source solutions. Through it flow requests from corporate clients, startups, and developers worldwide, making any vulnerability in its infrastructure a potentially large-scale problem.
The LiteLLM team has not disclosed details about the scale of the data breach and whether end users were affected. However, the decision to publicly break ties with Delve suggests that management views this partnership choice as a reputational and operational risk. This story clearly shows how vulnerable the supply chain is in AI infrastructure.
Intermediary tools, like AI gateways, become critical nodes — and any weakness in their partner ecosystem immediately becomes a risk for all who rely on them.
Need AI working inside your business — not just in your newsfeed?
I build production AI for companies — custom CRM, internal tools, autonomous agents, workflow automation. Owned by you, shaped to your process, no per-seat tax. Built by Zhemal Khamidun, CPO of AlpinaGPT (AI platform, 6,000+ users).
The AI world, distilled — once a week
Seven stories that actually mattered, hand-picked. No noise, no reposts, no press releases.
Done! Check your inbox for a confirmation.